Junglewise Threat Intelligence

CVE-2026-83089: Oracle E-Business Suite Alert privilege escalation via HTTP

CVE-2026-83089 · Severity: high · CVSS 8.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Alert is a critical notification system within the Oracle E-Business Suite, used by enterprises to manage workflow alerts and data notifications. This vulnerability allows a low-privileged network user to gain unauthorized access to sensitive data or modify critical business records without proper authorization, potentially exposing customer data or enabling fraudulent transactions.

Technical details

This is an access control vulnerability in the Oracle Alert component of E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable over the network (HTTP) by a low-privileged authenticated attacker with no user interaction required. Successful exploitation permits unauthorized creation, deletion, or modification of critical data within Oracle Alert, as well as unauthorized read access to all Alert-accessible data. The attack requires network access and low-level privileges but does not require administrative credentials. No patch availability information is currently available from the advisory text.

Affected products

  • Oracle E-Business Suite Alert 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References